package com.hn.y.config;

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@Configuration
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http.formLogin()
                .loginProcessingUrl("/login")
                .loginPage("/login.html")
                .successForwardUrl("/index");

        http.authorizeRequests()
                .antMatchers("/login.html").permitAll();


        //关闭csrf 生产环境需要打开，高版本默认已经打开
        http.csrf().disable();
    }
}
